Xxe

Advanced XML External Entity (XXE) testing methodology for bug bounty and application security work. Use when testing or reviewing XML parsers, SOAP/SAML/SXMP processors, Office/PDF/image metadata parsers, XMP metadata in JPEGs, SVG/XML uploads, IVR or phone-to-XML workflows, document import/export, blind XXE, out-of-band XXE, local file disclosure, SSRF through XML entities, parser configuration mistakes, and workflows where attacker-controlled XML or metadata can resolve external entities.

yafet-dev Updated

File contents

yafet-dev/bugbounty-codex-skills/tree/main/bug-type-skills/xxe commit 1eed01bf77

Frequently asked questions

npx skillmds@latest add yafet-dev/xxe